CVE-2021-44159

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
20/12/2021
Last modified:
03/01/2022

Description

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:4mosan:gcb_doctor:*:*:*:*:*:*:*:* 2021-09-16 (excluding)


References to Advisories, Solutions, and Tools